CVE-2014-0471: Canonical Ubuntu Linux

Medium severity, CVSS 5.0. EPSS: 2.9% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.10 only; version 14.04 only
  • Debian Dpkg: up to and including 1.15.8.8; version 1.9.1 only; version 1.9.2 only; version 1.9.3 only; version 1.9.7 only; version 1.9.8 only; …

Published 2014-04-30. Last modified 2026-06-17.